rootpwn

critical · CVSS v3 8.6 · CVSS v4 8.8

CVE-2026-105115

OpenAM versions prior to 16.1.3 allow unauthenticated remote attackers to instantiate arbitrary classes via the legacy JAX‑RPC SOAP interfac

Overview

OpenAM versions prior to 16.1.3 allow unauthenticated remote attackers to instantiate arbitrary classes via the legacy JAX‑RPC SOAP interface, potentially crashing the server or enabling code execution. The vulnerability is triggered by sending crafted SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name. It poses a critical risk to any deployment exposing the legacy SOAP endpoint.

Description

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.

Impact

The flaw compromises confidentiality, integrity, and availability of the affected OpenAM instance. Attackers can crash the server, enumerate the classpath, or chain gadget payloads for remote code execution, thereby impacting all users and services relying on the compromised authentication server.

Remediation

Apply the official patch to upgrade to OpenAM 16.1.3 or later. If upgrading is not immediately possible, disable the legacy JAX‑RPC SOAP endpoint or block access to /jaxrpc/* via firewall or application configuration. Ensure session identifiers are validated before processing SOAP requests.

Risk context

The vulnerability is rated critical with a CVSS v3 score of 8.6 and CVSS v4 score of 8.8. No EPSS data is available, but the lack of authentication makes the risk immediate for exposed instances.

Affected products

  • ForgeRock OpenAM 16.1.2
  • ForgeRock OpenAM 16.1.1
  • ForgeRock OpenAM 16.1.0

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.6
CVSS v4
8.8
EPSS
—

OpenAM SOAP ClassInstantiation Critical Remote LegacyInterface ForgeRock

← All CVEs